htslib records
16 published records for vendor htslib.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 31.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read4
- CWE-122 Heap-based Buffer Overflow4
- CWE-121 Stack-based Buffer Overflow2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-772 Missing Release of Resource after Effective Lifetime1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-1000206No exploit | samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary chtslib · htslib · CWE-119 | Critical9.8 | — | 2.0% | Nov 17, 2017 |
39Monitor | CVE-2018-13845No exploit | An issue has been found in HTSlib 1.8.htslib · htslib · CWE-125 | Critical9.8 | — | 1.6% | Jul 10, 2018 |
35Monitor | CVE-2020-36403No exploit | HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).htslib · htslib · CWE-787 | High8.8 | — | 1.6% | Jun 30, 2021 |
35Monitor | CVE-2026-31962No exploit | HTSlib CRAM reader has heap buffer overflow due to improper validation of inputhtslib · htslib · CWE-122 | High8.8 | — | 0.6% | Mar 18, 2026 |
35Monitor | CVE-2026-31968No exploit | HTSlib CRAM decoder vulnerable to buffer overflowhtslib · htslib · CWE-121 | High8.8 | — | 0.5% | Mar 18, 2026 |
35Monitor | CVE-2026-31963No exploit | HTSlib CRAM reader has heap buffer overflow due to improper validation of inputhtslib · htslib · CWE-122 | High8.8 | — | 0.5% | Mar 18, 2026 |
30Monitor | CVE-2018-13843No exploit | An issue has been found in HTSlib 1.8.htslib · htslib · CWE-772 | High7.5 | — | 1.5% | Jul 10, 2018 |
30Monitor | CVE-2018-13844No exploit | An issue has been found in HTSlib 1.8.htslib · htslib · CWE-401 | High7.5 | — | 1.4% | Jul 10, 2018 |
28Monitor | CVE-2026-31970No exploit | HTSlib BGZF index file reader has a heap buffer overflowhtslib · htslib · CWE-122 | High7.1 | — | 0.6% | Mar 18, 2026 |
28Monitor | CVE-2026-31971No exploit | HTSlib CRAM decoder vulnerable to buffer overflowhtslib · htslib · CWE-121 | High7.1 | — | 0.5% | Mar 18, 2026 |
28Monitor | CVE-2026-31969No exploit | HTSlib CRAM decoder has a heap buffer overflowhtslib · htslib · CWE-122 | High7.1 | — | 0.5% | Mar 18, 2026 |
27Monitor | CVE-2026-31966No exploit | HTSlib CRAM reader has out-of-bounds read due to improper validation of inputhtslib · htslib · CWE-125 | Medium6.9 | — | 0.7% | Mar 18, 2026 |
27Monitor | CVE-2026-31967No exploit | HTSlib CRAM reader has out-of-bounds read due to improper validation of inputhtslib · htslib · CWE-125 | Medium6.9 | — | 0.5% | Mar 18, 2026 |
27Monitor | CVE-2026-31964No exploit | HTSlib CRAM decoder has a NULL Pointer Dereferencehtslib · htslib · CWE-476 | Medium6.9 | — | 0.5% | Mar 18, 2026 |
27Monitor | CVE-2026-31965No exploit | HTSlib CRAM reader has out-of-bounds reads due to improper validation of inputhtslib · htslib · CWE-125 | Medium6.9 | — | 0.5% | Mar 18, 2026 |
18Monitor | CVE-2018-14329No exploit | In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack.htslib · htslib · CWE-59 | Medium4.7 | — | 0.2% | Jul 16, 2018 |
- CVE-2017-100020640Plan
samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary c
CriticalCVSS 9.8No exploitEPSS 2%htslib · htslibNov 17, 2017
- CVE-2018-1384539Monitor
An issue has been found in HTSlib 1.8.
CriticalCVSS 9.8No exploitEPSS 2%htslib · htslibJul 10, 2018
- CVE-2020-3640335Monitor
HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).
HighCVSS 8.8No exploitEPSS 2%htslib · htslibJun 30, 2021
- CVE-2026-3196235Monitor
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
HighCVSS 8.8No exploitEPSS 1%htslib · htslibMar 18, 2026
- CVE-2026-3196835Monitor
HTSlib CRAM decoder vulnerable to buffer overflow
HighCVSS 8.8No exploitEPSS 1%htslib · htslibMar 18, 2026
- CVE-2026-3196335Monitor
HTSlib CRAM reader has heap buffer overflow due to improper validation of input
HighCVSS 8.8No exploitEPSS 1%htslib · htslibMar 18, 2026
- CVE-2018-1384330Monitor
An issue has been found in HTSlib 1.8.
HighCVSS 7.5No exploitEPSS 1%htslib · htslibJul 10, 2018
- CVE-2018-1384430Monitor
An issue has been found in HTSlib 1.8.
HighCVSS 7.5No exploitEPSS 1%htslib · htslibJul 10, 2018
- CVE-2026-3197028Monitor
HTSlib BGZF index file reader has a heap buffer overflow
HighCVSS 7.1No exploitEPSS 1%htslib · htslibMar 18, 2026
- CVE-2026-3197128Monitor
HTSlib CRAM decoder vulnerable to buffer overflow
HighCVSS 7.1No exploitEPSS 1%htslib · htslibMar 18, 2026
- CVE-2026-3196928Monitor
HTSlib CRAM decoder has a heap buffer overflow
HighCVSS 7.1No exploitEPSS 1%htslib · htslibMar 18, 2026
- CVE-2026-3196627Monitor
HTSlib CRAM reader has out-of-bounds read due to improper validation of input
MediumCVSS 6.9No exploitEPSS 1%htslib · htslibMar 18, 2026
- CVE-2026-3196727Monitor
HTSlib CRAM reader has out-of-bounds read due to improper validation of input
MediumCVSS 6.9No exploitEPSS 1%htslib · htslibMar 18, 2026
- CVE-2026-3196427Monitor
HTSlib CRAM decoder has a NULL Pointer Dereference
MediumCVSS 6.9No exploitEPSS 0%htslib · htslibMar 18, 2026
- CVE-2026-3196527Monitor
HTSlib CRAM reader has out-of-bounds reads due to improper validation of input
MediumCVSS 6.9No exploitEPSS 0%htslib · htslibMar 18, 2026
- CVE-2018-1432918Monitor
In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack.
MediumCVSS 4.7No exploitEPSS 0%htslib · htslibJul 16, 2018